CVE-2026-77639
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under
CVSS
5.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 20, 2026 · Last modified: Aug 20, 2026 · CWE-420
Not enough EPSS history yet.
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-402178.8 HIG93.2%
——28LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.38dCVE-2026-353882.5 LOW3.1%
——1OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.28d